Legal
Security
Encryption
- TLS 1.3 for all data in transit
- AES-256 encryption for data at rest
- End-to-end encryption for sensitive communications
- Secure key management system
Access control
- Multi-factor authentication (MFA)
- Role-based access control (RBAC)
- Regular access reviews
- Audit logging of all access attempts
Infrastructure
- Regular security audits and penetration testing
- DDoS protection and mitigation
- Automated threat detection
- Tenant isolation across every workspace
Incident response
- Incident response team available 24/7
- Documented incident response procedures
- Regular security drills and tabletop exercises
- Transparent security incident reporting
What we do with your call data
We don't train on your calls
Your recordings, transcripts, and contact data are used to deliver your service. They aren't used to train models, ours or anyone else's.
Your data is exportable
Calls, transcripts, recordings, and contacts are available through the API. If you leave, you take everything with you.
Tenant isolation
Every workspace is scoped to its own account. Data is not shared, pooled, or aggregated across customers.
Subprocessors
We use third parties for telephony, speech, and infrastructure. Which ones depends on how your agents are configured — ask and we'll give you the current list in writing.
Questions we get from security reviews
Do you have SOC 2 / ISO 27001?
Ask us for our current compliance status rather than relying on a badge on a marketing page. We'd rather tell you exactly where we are — including what we don't have yet — than imply something we can't evidence.
Where is data stored?
It depends on your configuration and the providers your agents use. If you have a data residency requirement, raise it before you build — it's much easier to answer up front than to retrofit.
Can we get a DPA?
Yes. Email [email protected] and we'll get one to you.
How do we report a vulnerability?
Email [email protected] with enough detail to reproduce it. We'll acknowledge it, and we won't take legal action against good-faith research that doesn't degrade the service or touch other customers' data.
Are calls recorded, and is that legal?
Recording is configurable, and consent capture runs on the call path where it's required. Recording law varies by jurisdiction and by who's on the call — the platform gives you the controls, but the obligation to use them correctly is yours.
Reporting a vulnerability
Send it to [email protected] with enough detail to reproduce. We'll acknowledge it and keep you posted on the fix. We won't pursue good-faith research that avoids degrading the service and doesn't touch other customers' data.